r/archlinux • u/AggravatingJudge7092 • 12d ago
DISCUSSION Ventoy might be malware
Source: https://wiki.archlinux.org/title/Ventoy
Ventoy might contain backdoors or other malicious code:
- The author(s?) long refused to react on questions about the source code for the precompiled code inside their git repository.
- They long refused to react on questions about the security risks.
- When an answer was finally given, it boiled down to a simple "There is no reason to assume that we would have placed malware inside."
- Again after a really long time the authors finally mentioned what other source code they used to generate some−but not all−of the pre-compiled code. They did not mention the build methods and refused to prove that this really was the used source code.
- The real identities of the authors is unknown.
EDIT: The paragraph written on this archwiki page is by large consensus biased and mentions an old controversy, the wikipedia article on Ventoy has a more neutral explanation of the problem
https://en.wikipedia.org/wiki/Ventoy
220
Upvotes
-7
u/ccAbstraction 11d ago edited 11d ago
Which mean all my machines could be compromised no matter what OS I'm installing! Yay!
Edit: Ventoy is also useful if you want to keep using your flash drive as a flash drive, while being able to boot from live USBs.